Record summary

CVE-2022-48197 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 28, 2024 · Source: CVE List

Proofs of concept

2

Catalogued exploits

ExploitDBYahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)ExploitDB exploitby SITE TeamNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubryan412/CVE-2022-48197Repository PoCby ryan412Stars: 0Not analyzed1 file

1.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMYahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site ScriptingCVSS 6.1

Reflected cross-site scripting (XSS) exists in the TreeView of YUI2 through 2800: up.php sam.php renderhidden.php removechildren.php removeall.php readd.php overflow.php newnode2.php newnode.php.

Impact

Attackers can inject malicious JavaScript through crafted mode parameters in multiple TreeView PHP files, potentially stealing user session tokens and performing actions on behalf of victims when they access the compromised pages.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
Authorsctflearner
Template tagscvecve2022packetstormyui2xssyahootreeviewyui_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:yui_project:yui:*:*:*:*:*:*:*:*
Shodan: html:"bower_components/yui2/"
Shodan: http.html:"bower_components/yui2/"
FOFA: body="bower_components/yui2/"

Source: ProjectDiscovery

References

7